RHSA-2014:1007: Important: Red Hat JBoss BRMS 5.3.1 update
Red Hat JBoss BRMS is a business rules management system for themanagement, storage, creation, modification, and deployment of JBoss Rules.This roll up patch serves as a cumulative upgrade for Red Hat JBoss BRMS5.3.1. It includes various bug fixes. The following security issues arealso fixed with this release:It was found that XStream could deserialize arbitrary user-supplied XMLcontent, representing objects of any type. A remote attacker able to passXML to XStream could use this flaw to perform a variety of attacks,including remote code execution in the context of the server running theXStream application. (CVE-2013-7285)It was found that the secure processing feature of Xalan-Java hadinsufficient restrictions defined for certain properties and features.A remote attacker able to provide Extensible Stylesheet LanguageTransformations (XSLT) content to be processed by an application usingXalan-Java could use this flaw to bypass the intended constraints of thesecure processing feature. Depending on the components available in theclasspath, this could lead to arbitrary remote code execution in thecontext of the application server running the application that usesXalan-Java. (CVE-2014-0107)All users of Red Hat JBoss BRMS 5.3.1 as provided from the Red Hat CustomerPortal are advised to apply this roll up patch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2014:1007?
The severity of RHSA-2014:1007 is classified as important.
How do I fix RHSA-2014:1007?
To fix RHSA-2014:1007, you should apply the latest cumulative patch available for Red Hat JBoss BRMS version 5.3.1.
What vulnerabilities does RHSA-2014:1007 address?
RHSA-2014:1007 addresses various security vulnerabilities in Red Hat JBoss BRMS 5.3.1.
Is RHSA-2014:1007 applicable to all versions of Red Hat JBoss BRMS?
No, RHSA-2014:1007 is specifically applicable to Red Hat JBoss BRMS version 5.3.1.
When was RHSA-2014:1007 released?
RHSA-2014:1007 was released on March 18, 2014.